{
  "schema": "metatron.intelligence.governance-crosswalk.v1",
  "version": "1.0.0",
  "researchCutoff": "2026-09-03",
  "status": "method_registry_not_conformity_assessment",
  "purpose": "Keep governance, incident, legal and vulnerability concepts separately addressable before any reviewed mapping is published.",
  "relationVocabulary": [
    "exact",
    "partial",
    "related",
    "conflict",
    "none"
  ],
  "frameworks": [
    {
      "namespace": "NIST_AI_RMF",
      "version": "1.0",
      "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0)",
      "publisher": "National Institute of Standards and Technology",
      "date": "2023-01",
      "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
      "scope": "Voluntary AI risk-management outcomes across GOVERN, MAP, MEASURE and MANAGE.",
      "boundary": "A mapping is not proof that a control is adequate, implemented or compliant; version 1.0 was under revision at the research cut-off."
    },
    {
      "namespace": "NIST_AI_600_1",
      "version": "1.0",
      "title": "Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile",
      "publisher": "National Institute of Standards and Technology",
      "date": "2024-07-26",
      "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf",
      "scope": "Generative-AI risk actions including logging, incident documentation, near-misses, response and after-action learning.",
      "boundary": "A voluntary profile, not a reporting law or exhaustive incident taxonomy."
    },
    {
      "namespace": "OECD_AI_INCIDENT_REPORTING",
      "version": "2025-02-28",
      "title": "Towards a common reporting framework for AI incidents",
      "publisher": "OECD",
      "date": "2025-02-28",
      "url": "https://oecd.ai/en/ai-publications/towards-a-common-reporting-framework-for-ai-incidents",
      "scope": "A common, tailorable reporting format with incident criteria and dimensions.",
      "boundary": "A reporting framework is not a finding that an incident occurred and is not a binding duty."
    },
    {
      "namespace": "OECD_AIM",
      "version": "methodology-since-2024-11",
      "title": "Overview and methodology of the AI Incidents and Hazards Monitor",
      "publisher": "OECD.AI / OECD",
      "date": null,
      "url": "https://oecd.ai/en/incidents-methodology",
      "scope": "Separates incidents involving actual harm from hazards involving plausible harm and documents a media/model-assisted discovery pipeline.",
      "boundary": "Discovery and clustering do not independently verify accuracy, completeness or validity."
    },
    {
      "namespace": "EU_AI_ACT",
      "version": "Regulation-EU-2024-1689-consolidated-2026-07-27",
      "title": "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence",
      "publisher": "European Parliament and Council via EUR-Lex",
      "date": "2024-06-13",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689",
      "scope": "Namespaced legal concepts including serious incident in Article 3(49) and the Article 73 reporting pathway.",
      "boundary": "Legal applicability is never inferred by the wiki; it requires jurisdiction-, actor- and system-specific qualified review."
    },
    {
      "namespace": "ISO_IEC_42001",
      "version": "2023",
      "title": "ISO/IEC 42001:2023 — Artificial intelligence management system",
      "publisher": "ISO / IEC",
      "date": "2023-12",
      "url": "https://www.iso.org/standard/81230.html",
      "scope": "Public abstract supports an organisational AI management system and continual improvement.",
      "boundary": "Public abstract only; no clause-level mapping, certification or conformity claim is permitted without authorised normative text."
    },
    {
      "namespace": "CISA_VDP",
      "version": "BOD-20-01",
      "title": "BOD 20-01: Develop and Publish a Vulnerability Disclosure Policy",
      "publisher": "Cybersecurity and Infrastructure Security Agency",
      "date": "2020-09-02",
      "url": "https://www.cisa.gov/sites/default/files/bod-20-01.pdf",
      "scope": "Process precedent for an authorised reporting channel, scope, expectations, tracking and coordinated remediation.",
      "boundary": "Its binding scope is U.S. federal civilian agencies and cybersecurity vulnerabilities, not general AI intelligence contributions."
    },
    {
      "namespace": "CVE_RECORD_FORMAT",
      "version": "5.2.0",
      "title": "CVE Record Format",
      "publisher": "CVE Project / CVE Quality Working Group",
      "date": null,
      "url": "https://github.com/CVEProject/cve-schema/blob/ce5f5c865f14dc40a6548d36b74751abca1c588a/schema/docs/CVE_Record_Format_bundled.json",
      "scope": "Technical precedent for stable IDs, versioned schemas, controlled states, publisher metadata, timestamps, revisions and source containers.",
      "boundary": "CVE models public cybersecurity vulnerabilities; CVE IDs and states must never be fabricated or repurposed for AI incidents."
    }
  ],
  "mappingContract": {
    "requiredFields": [
      "mappingId",
      "sourceNamespace",
      "sourceVersion",
      "sourceElement",
      "targetNamespace",
      "targetVersion",
      "targetElement",
      "relation",
      "direction",
      "rationale",
      "limitation",
      "mapperRole",
      "reviewerRole",
      "reviewedAt"
    ],
    "rules": [
      "Pin every source and target version.",
      "Map exact elements, not document names or topical similarity.",
      "State direction and cardinality; never assume a bidirectional mapping.",
      "Publish a rationale and the omitted-content limitation.",
      "Keep framework-mapping confidence separate from event-evidence confidence and legal applicability.",
      "Preserve conflicts and none relations instead of forcing equivalence.",
      "An upstream version change marks affected mappings review_due; it never changes an editorial conclusion automatically.",
      "ISO clause and conformity mappings require authorised clause-level evidence."
    ]
  },
  "globalBoundary": "This registry documents source namespaces and mapping rules. It contains no claim that Metatron, a system, an incident or a control conforms with any listed framework."
}
